CSIDB logo
Threat actor

TheHorsemen

Attribution profile

Type
Activist
Location
China
Known incidents
1 incident
Sources
1 source
First seen
2014-02-10
Last seen
2014-02-10
Updated
2026-07-31 20:36
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

TheHorsemen is an alias used by a threat actor that has been publicly linked to China. On February 10 2014 the actor claimed responsibility for compromising the official social media presences of the Dubai Police, gaining access to the Twitter, Pinterest, LinkedIn and Tumblr accounts associated with the organization. After obtaining control, the actor posted screenshots that demonstrated the successful intrusion and accompanied them with a message alleging that the police were conducting surveillance on citizens. The posted content was later removed, and while the Dubai Police did not issue a public statement, the Dubai Media Office confirmed that the accounts had been subjected to a cyberattack. This incident was presented as part of a broader operation referred to as OpDubai. The actor’s alias appears in the Softpedia article with source report ID 00250d1c‑2ae2‑48ab‑8a6f‑fb3a5f47d02b, which provides the primary public record of the activity. No other incidents attributed to TheHorsemen have been documented in open‑source reporting beyond this 2014 event. The actor’s location is noted as China in the contextual information provided, although no further geographic details are disclosed.

OpDubai, the campaign under which the Dubai Police breach occurred, had previously targeted multiple government websites within the United Arab Emirates, causing disruption to their online services. The actor’s activity therefore demonstrates a focus on governmental entities in the UAE, with the apparent strategic objective of disrupting their digital presence rather than pursuing financial gain or espionage. The only technique explicitly described in the reporting is the acquisition of unauthorized access to social media platforms, after which the actor used the compromised accounts to disseminate proof‑of‑concept screenshots and a protest message. No public sources have attributed the actor to a specific state sponsor or criminal consortium, and beyond the location indicator of China no further details about affiliations, infrastructure, or tooling have been disclosed. Consequently, the known profile of TheHorsemen remains limited to the described OpDubai actions and the associated social media compromise, with no additional publicly verified through the single cited source.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB